Why this page exists
Buyers, CISOs, and journalists often treat every “security organisation in Hong Kong” as interchangeable. That creates two problems: people contact the wrong channel during an incident, and they misread Trust Reviews as if they were government clearances.
This page explains the difference in plain language — and how to use both correctly for Hong Kong cybersecurity and AI security work.
Short answer
HKCERT (Hong Kong Computer Emergency Response Team Coordination Centre) is Hong Kong’s public Computer Emergency Response Team. It is the coordination point people should use for incident response, official advisories, and national cyber hygiene programmes.
HKISG (Hong Kong Information Security Group) is an independent membership organisation. We publish education, security news, methodology-based Trust Reviews, security bulletins, and practitioner materials spanning classical cyber controls and AI security. We are not a government department, regulator, or national CERT.
If you remember only one rule: HKCERT for national incident coordination; HKISG for inspectable trust signals, education, and programme methodology.
Side-by-side comparison
When to use which
Use this decision path before you escalate:
- Systems are actively compromised, ransomware is spreading, or you need national CERT help → go to HKCERT first.
- You need an early-warning note with HKISG risk labels and operator cues → Security Bulletins.
- You need a dated public trust profile (including AI lenses and website hygiene) → Trust Reviews and Methodology.
- The board asks “what should we learn about AI risk?” → Online Education, AI Security wiki, and Prompt Injection.
- The question is personal data / PDPO / automated decisions → PCPD for regulatory guidance, plus HKISG’s privacy wiki and PDPO news context.
Typical Hong Kong scenarios
Scenario A — Edge appliance zero-day
Patch and contain using vendor + HKCERT guidance. Use HKISG bulletins/news for board language and evidence capture if you later enter a Trust Review.
Scenario B — AI chatbot may have leaked customer data
Treat it as both an incident (HKCERT / legal / PCPD pathways as applicable) and an AI security control failure (inventory, prompt/tool abuse, human oversight). HKISG methodology domains describe the control language; they do not replace CERT response.
Scenario C — Vendor claims “CERT-approved” because of an HKISG star
That claim is wrong. TrustScores are independent programme outcomes, not CERT clearances. Ask for scope, date, methodology version, and limitations on the public review page.
How HKISG references HKCERT
HKISG articles and bulletins often point readers to HKCERT when national coordination or official advisories apply. Citing HKCERT does not mean HKISG speaks for HKCERT, and it does not create a joint certification.
If an HKISG page and an HKCERT advisory conflict on urgency or technical remediation, follow the CERT advisory for incident response. Then use HKISG materials for:
- board and risk-committee framing
- Trust Review evidence packs
- AI security literacy and methodology alignment
- education pathways for teams
AI security: what each organisation does — and does not do
Neither HKCERT nor HKISG “certifies” that an AI product is permanently safe.
HKISG’s Methodology v2026.2 treats AI security as a first-class domain: model/GenAI inventory, abuse testing (including prompt injection), data integrity, human oversight, third-party LLM risk, and AI-assisted defence discipline. Product-level white-hat recognition, when applicable, sits under IT Awards.
HKCERT remains the coordination reference when AI-enabled attacks become active incidents (for example large-scale deepfake fraud campaigns or exploited AI features in widely used platforms).
Common misconceptions
- “HKISG is a government body.” No. Independent membership organisation.
- “A 5.0 TrustScore means HKCERT cleared the vendor.” No. Different programmes entirely.
- “If HKCERT published an advisory, I do not need HKISG.” You may still need education, Trust Reviews, or board materials — different job.
- “Membership buys stars.” No. Fees fund capacity; scores follow published rules under Governance.
Hong Kong operator checklist
- Bookmark HKCERT for incident and advisory channels; test that your on-call team knows the path.
- Subscribe to HKISG Security News and Bulletins for operator context between major advisories.
- Never treat TrustScores as CERT clearances in RFPs or press quotes.
- Keep a dated evidence pack (tickets, patch timestamps, AI inventory notes) whenever you act on either source.
- For AI systems, maintain owners, abuse-test notes, and human-confirmation gates — see Prompt Injection.
- Separate privacy questions (PCPD / PDPO) from CERT response and from Trust Review scoring.
Related HKISG resources
- Security Bulletins
- Security News
- Assessment Methodology
- Trust Reviews
- AI Security and Governance
- Policies & Standards
- Governance & Integrity
- Contact HKISG
Editorial note
Published by the Hong Kong Information Security Group for educational clarity. Always verify current HKCERT guidance on hkcert.org. This page is not legal advice, not a regulatory opinion, and not a substitute for national CERT coordination.